Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to execute shell scripts as root and to install system packages, create users, modify ACLs, and place a wrapper in /usr/local/bin, yet it declares no permissions. This creates a misleading trust boundary: a caller or platform may treat the skill as low-privilege while it actually performs privileged host-level operations, increasing the risk of unauthorized system changes if invoked in the wrong context.
